{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/jailbreaking-attack-against-multimodal-large","title":"Jailbreaking Attack against Multimodal Large Language Model","arxiv_id":"2402.02309","date":"2024-02-04","proceeding":null,"authors":["Zhenxing Niu","Haodong Ren","Xinbo Gao","Gang Hua","Rong Jin"],"abstract":"This paper focuses on jailbreaking attacks against multi-modal large language models (MLLMs), seeking to elicit MLLMs to generate objectionable responses to harmful user queries. A maximum likelihood-based algorithm is proposed to find an \\emph{image Jailbreaking Prompt} (imgJP), enabling jailbreaks against MLLMs across multiple unseen prompts and images (i.e., data-universal property). Our approach exhibits strong model-transferability, as the generated imgJP can be transferred to jailbreak various models, including MiniGPT-v2, LLaVA, InstructBLIP, and mPLUG-Owl2, in a black-box manner. Moreover, we reveal a connection between MLLM-jailbreaks and LLM-jailbreaks. As a result, we introduce a construction-based method to harness our approach for LLM-jailbreaks, demonstrating greater efficiency than current state-of-the-art methods. The code is available here. \\textbf{Warning: some content generated by language models may be offensive to some readers.}","url_abs":"https://arxiv.org/abs/2402.02309v1","url_pdf":"https://arxiv.org/pdf/2402.02309v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"jailbreaking-attack-against-multimodal-large","repo_url":"https://github.com/abc03570128/jailbreaking-attack-against-multimodal-large-language-model","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"pytorch","reach":{"status":"ok"}},{"paper_slug":"jailbreaking-attack-against-multimodal-large","repo_url":"https://github.com/naver-ai/jood","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"language-modeling","task_name":"Language Modeling"},{"task_slug":"language-modelling","task_name":"Language Modelling"},{"task_slug":"large-language-model","task_name":"Large Language Model"},{"task_slug":"multimodal-large-language-model","task_name":"Multimodal Large Language Model"},{"task_slug":"model","task_name":"model"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2402.02309","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2402.02309"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/naver-ai/jood","reach":null},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/abc03570128/jailbreaking-attack-against-multimodal-large-language-model","reach":{"status":"ok"}}],"summary":{"ran_violates":1,"ran_draft_wrong":2,"ran":1},"by_repo_kind":{"official":{"samples":3,"ran":3,"repositories":1},"listed":{"samples":1,"ran":1,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":3,"samples":[{"code_sha256_prefix":"4cb732f513d69dfd","entry":"disabled_train","repo":"abc03570128/jailbreaking-attack-against-multimodal-large-language-model","repo_kind":"official","path":"minigpt4/models/base_model.py","file_url":"https://github.com/abc03570128/jailbreaking-attack-against-multimodal-large-language-model/blob/HEAD/minigpt4/models/base_model.py","link_basis":"harvester_set","language":"python","status":"ran_violates","verification_level":1,"contract_check":"VIOLATES","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"4cb732f513d69dfd"}},{"code_sha256_prefix":"82dfbc3db8906d82","entry":"extract_info","repo":"naver-ai/jood","repo_kind":"listed","path":"evaluate_metrics.py","file_url":"https://github.com/naver-ai/jood/blob/HEAD/evaluate_metrics.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"Apache-2.0","inline_ok":true,"mcp_get_code":{"code_sha256":"82dfbc3db8906d82"}},{"code_sha256_prefix":"0008906f1146d6c5","entry":"my_norm","repo":"abc03570128/jailbreaking-attack-against-multimodal-large-language-model","repo_kind":"official","path":"v1_Mprompt_Mimage.py","file_url":"https://github.com/abc03570128/jailbreaking-attack-against-multimodal-large-language-model/blob/HEAD/v1_Mprompt_Mimage.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"0008906f1146d6c5"}},{"code_sha256_prefix":"9b45cb80d93fe980","entry":"wrapper_method","repo":"abc03570128/jailbreaking-attack-against-multimodal-large-language-model","repo_kind":"official","path":"torchattacks/attack.py","file_url":"https://github.com/abc03570128/jailbreaking-attack-against-multimodal-large-language-model/blob/HEAD/torchattacks/attack.py","link_basis":"plan_row","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"9b45cb80d93fe980"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}